Legal
Privacy Policy
Last updated: July 15, 2026
Contents
Who we are
GrydBase is a business operations platform for contractors, roofers, service businesses, and similar trades. It is owned and operated by Caleb Media Studio, LLC ("we", "us", "our"), based in Central Florida. This Privacy Policy explains what data we collect, how we use it, and what rights you have over it.
"You" means anyone who creates an account, uses the platform, or accesses a client portal created through GrydBase.
Data we collect
Account data: When you register, we collect your name, email address, and authentication credentials. If you sign in with Google, we receive your name and email from Google but never your Google password.
Workspace and business data: Data you enter into GrydBase — customer contacts, job records, notes, invoices, contracts, and site content — is stored on your behalf. You own this data.
Contract and signature data: When a workspace uses contract or electronic-signature features, we process contract content and attachments, names, email addresses, business information, signatures, initials, consent records, IP addresses, user agents, access and signing timestamps, delivery records, document hashes, audit events, completed contracts, and archived agreements.
Consumer disclosure data: Where consumer disclosure mode is used, we process the consumer disclosure text and version, hardware and software requirements, paper-copy and withdrawal terms, and the scope of consent.
Email content: When you use GrydBase's business email feature, inbound and outbound message content is stored to display in your inbox and linked to CRM records. Email delivery is handled by a third-party provider (see Section 5).
Payment data: We do not store credit card numbers or raw payment credentials. Payment details are handled entirely by our payment processor. We receive transaction IDs, billing amounts, and subscription status via secure webhook events.
Technical data: We collect IP addresses, browser type, device information, and session tokens for security, authentication, and platform reliability purposes. This data is not sold or used for advertising.
AI interaction data: When you use AI features, your prompt and relevant workspace context (contact records, site content, etc.) are sent to our AI model provider to generate a response. See Section 6 for details.
How we use your data
We use your data to:
- Provide, maintain, and improve the GrydBase platform
- Authenticate your identity and secure your workspace
- Process payments and manage subscription billing
- Send transactional emails (invoices, receipts, portal invites, system alerts)
- Provide contract and electronic-signature services, authenticate signing activity, maintain document integrity, generate audit evidence, prevent fraud, resolve technical or security issues, retain agreements as required, and provide completed-document access
- Enable AI-powered features when you initiate them
- Comply with legal obligations and respond to valid legal requests
- Investigate and prevent fraud, abuse, and security incidents
We do not sell your personal data. We do not use your data to serve advertising.
The workspace customer controls the contract content and signing requests submitted through its workspace, and GrydBase processes that data to provide the service where applicable. Authorized administrators, support, security, or automated systems may access contract data when reasonably necessary to operate, secure, support, or investigate the service.
Third-party services
GrydBase relies on third-party infrastructure providers to operate. These providers handle specific functions including database hosting and authentication, application hosting and delivery, payment processing, transactional and business email delivery, AI model inference, domain registration, and DNS management.
Each provider receives only the data necessary to perform its function. We do not sell data to third parties, and none of our providers are authorized to use your data for their own marketing purposes.
All primary subprocessors we rely on maintain active SOC 2 Type 2 compliance — an independent third-party audit that verifies their security, availability, and confidentiality controls are operating effectively on an ongoing basis. We require the same standard from every infrastructure provider we add.
AI features and data handling
GrydBase uses an AI model provider to power features such as email drafting, site content generation, and workflow assistance. When you initiate an AI feature:
- Your prompt and relevant workspace context (e.g., a contact's name or a site section) are transmitted to our AI provider to generate a response
- Our AI provider does not use API-submitted data to train its models
- AI requests are never made automatically — they are always user-initiated
- AI context is limited to what is directly relevant to your specific request
We do not send payment data, authentication credentials, or full email inboxes to AI providers. Each AI request consumes actions from your workspace balance at the time of the request. AI-generated content is stored in your workspace only if you choose to save it.
Data retention
We retain your data for as long as your account is active and your subscription is in good standing.
- Workspace data (contacts, jobs, site content, notes, and files) — retained while your account is active; deleted or anonymized after account closure except where retention is required
- Billing, payment, invoice, and tax records — retained as required by applicable tax, accounting, and payment-processing obligations
- Signed contracts, signature evidence, consent records, and audit records — retained where needed as legal records or to resolve disputes
- Email delivery logs — retained for a limited operational period unless needed for abuse, compliance, or dispute review
- IP and security logs — retained for a limited security period unless needed to investigate abuse or protect the platform
If you cancel your subscription, your workspace data remains accessible for up to 30 days so you can export what you need. After that period, normal workspace content may be deleted or anonymized, except for records we must retain for legal, accounting, security, backup, or dispute-resolution purposes.
Completed agreements and related evidence may be retained according to workspace, legal, fraud-prevention, security, and dispute-resolution obligations. Account deletion may remove access before completed agreement evidence is permanently removed. Backup copies may persist for a limited delay before they are overwritten or expire, and legal, fraud, or security exceptions may apply.
Exporting your data
If you are located in the EEA, UK, or Switzerland, you have a right to data portability under the GDPR. If you are a California resident, you have a similar right under the CCPA/CPRA. You have the right to export your data at any time while your account is active. The following exports are available from your workspace settings:
- Contacts and CRM records — CSV export
- Invoices and contracts — PDF download per record
- Email messages — MBOX/EML format
- DNS records — Zone file export
- Site content — JSON export of page blocks
For a full bulk export of all workspace data, email support@grydbase.com with the subject "Data Export Request." We will deliver a complete archive within 14 business days.
Deleting your data
If you are located in the EEA, UK, or Switzerland, you have a right to erasure under the GDPR. If you are a California resident, you have a similar right to delete under the CCPA/CPRA. You can request deletion of your account and all associated personal data at any time from Account settings → Delete my account. You can also email support@grydbase.com if you need help.
Once you request deletion, we will:
- Schedule your account for permanent deletion 14 days out, giving you a window to cancel the request
- If you are the sole owner of a workspace, close that workspace and delete or anonymize normal workspace content while retaining legally necessary financial records, signed agreements, consent records, audit records, and backup copies
- Permanently delete your user account and profile once the 14-day period elapses
- Notify you by email when deletion is scheduled and if it is completed or canceled
What we are required to retain: Billing, payment, invoice, tax, signed contract, signature evidence, consent, audit, and security records may be retained where required by law or reasonably needed to resolve disputes, prevent abuse, or document legally significant actions. These records are restricted to those purposes and are purged or anonymized when the retention reason expires.
Ordinary workspace UI deletion does not delete completed agreements or their signature evidence. Those records follow the retention practices described above.
Domain registrations are governed by ICANN policy and cannot be deleted mid-registration period. They expire naturally at the end of their registration term unless renewed.
White label and reseller use
Agency plan subscribers may configure GrydBase with custom branding. When white-label is enabled, your customers interact with your branded interface and may not be aware they are using GrydBase. In this case, you are acting as a data controller for your customers' data, and we are acting as your data processor.
You are responsible for providing your own privacy notice to your customers explaining how their data is collected and used when they access your white-labeled portal. Our Privacy Policy governs the relationship between you and us, not between you and your end customers.
In general use of GrydBase, we act as a data processor for the business and client data you store in your workspace. Our Data Processing Agreement applies automatically to every workspace. If you need a countersigned copy for your own compliance records (for example, GDPR Article 28), contact support@grydbase.com.
Service availability and infrastructure
We design GrydBase for the highest possible reliability. However, GrydBase is built on top of third-party infrastructure — including Vercel (hosting), Supabase database hosting, application delivery, payments, and email delivery. The availability of these services is outside our direct control.
In the event of an outage or service degradation, we will work in good faith to restore full functionality as quickly as possible and communicate status updates through your workspace or registered email address.
We do not guarantee uninterrupted access to GrydBase and are not liable for data delays or loss of access caused by third-party infrastructure failures.
Security
We use industry-standard security practices to protect your data, including:
- TLS encryption in transit for all data between your browser and our servers
- Encrypted storage for sensitive values (API keys, webhook secrets)
- Row-level security enforced at the database layer to isolate tenant data
- Session tokens rotated on sign-in and invalidated on sign-out
- Service role credentials never exposed to client-side code
No system is perfectly secure. If you discover a vulnerability, please report it responsibly to support@grydbase.com.
Data breach notification: If we become aware of a security incident that compromises the confidentiality, integrity, or availability of your personal data, we will investigate promptly and notify affected users without undue delay, consistent with our obligations under applicable law (including GDPR notification timelines where they apply and relevant US state breach notification statutes). Notification will describe what happened, what data was involved, and the steps we are taking in response.
Children
GrydBase is intended for use by adults operating or working for businesses. In compliance with the Children's Online Privacy Protection Act (COPPA), we do not intentionally collect personal information from anyone under the age of 13, and we do not knowingly collect data from anyone under 18 years of age. If you believe a minor has provided us personal data, contact us immediately at support@grydbase.com and we will delete it promptly.
SMS and text messaging
If you provide a phone number and opt in, GrydBase may send you SMS text messages related to your account, workspace, onboarding, support requests, billing reminders, and other service notifications. We only collect SMS consent for messaging related to GrydBase.
We do not sell your phone number or SMS opt-in consent, and we do not share it with third parties for marketing or promotional purposes.
Message frequency varies. Message and data rates may apply. You can opt out at any time by replying STOP to any message, or get help by replying HELP or contacting sms@calebmedia.co.
Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by displaying a notice in your workspace at least 14 days before the changes take effect. Continued use of GrydBase after that date constitutes acceptance of the updated policy.
Contact
For questions, export requests, deletion requests, or privacy concerns, contact us at: support@grydbase.com
Caleb Media Studio, LLC · Central Florida, United States